CVE-2024-56409 is an unauthorized reflected cross-site scripting (XSS) vulnerability affecting PhpSpreadsheet versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7, specifically within the Currency.php file. An attacker can exploit this by manipulating the /vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.php script. Rated as MEDIUM severity with a CVSS score of 5.4, this vulnerability requires user interaction (UI:R) and low privileges (PR:L) for a successful attack, leading to potential low impact on confidentiality and integrity (C:L, I:L). The attack complexity is low (AC:L) and it is network-exploitable (AV:N). There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.29.7CPE matchmatch criteria | cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.1.6CPE matchmatch criteria | cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.3.5CPE matchmatch criteria | cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.7.0CPE matchmatch criteria | cpe:2.3:a:phpoffice:phpspreadsheet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.